Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
1294 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.57% | — | Php-fusion Phpfusion | 11/10/2021 | 17/6/2026 | PHPFusion 9.03.110 is affected by cross-site scripting (XSS) in the preg patterns filter html tag without "//" in descript() function An authenticated user can trigger XSS by appending "//" in the end of text. | |
| Modificada | Alta (7.8) | 2.3% | — | Corel PDF Fusion | 1/10/2021 | 17/6/2026 | Corel PDF Fusion 2.6.2.0 is affected by a Heap Corruption vulnerability when parsing a crafted file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a… | |
| Modificada | Alta (7.8) | 3.2% | — | Corel PDF Fusion | 1/10/2021 | 17/6/2026 | Coreip.dll in Corel PDF Fusion 2.6.2.0 is affected by an Out-of-bounds Write vulnerability when parsing a crafted file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a… | |
| Modificada | Alta (7.8) | 2.9% | — | Corel PDF Fusion | 1/10/2021 | 17/6/2026 | Corel PDF Fusion 2.6.2.0 is affected by an Out-of-bounds Write vulnerability when parsing a crafted file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open… | |
| Modificada | Alta (7.2) | 0.90% | — | Huawei Fusioncompute | 28/9/2021 | 17/6/2026 | There is a command injection vulnerability in CMA service module of FusionCompute 6.3.0, 6.3.1, 6.5.0 and 8.0.0 when processing the default certificate file. The software constructs part of a command using external special input from users, but the software does not sufficiently validate the user input. Successful… | |
| Modificada | Alta (7.5) | 0.66% | — | Huawei Fusioncompute | 28/9/2021 | 17/6/2026 | There is an improper file upload control vulnerability in FusionCompute 6.5.0, 6.5.1 and 8.0.0. Due to the improper verification of file to be uploaded and does not strictly restrict the file access path, attackers may upload malicious files to the device, resulting in the service abnormal. | |
| Modificada | Media (6.1) | 0.77% | — | Activefusions Order Status Batch Change | 17/9/2021 | 17/6/2026 | Cross-site scripting vulnerability in Order Status Batch Change Plug-in (for EC-CUBE 3.0 series) all versions allows a remote attacker to inject an arbitrary script via unspecified vectors. | |
| Modificada | Alta (8.4) | 0.28% | — | Vmware FusionVmware WorkstationVmware Vsphere Esxi | 15/9/2021 | 17/6/2026 | VMware ESXi (6.7 before ESXi670-202006401-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.5), and Fusion (11.x before 11.5.5) contain an out-of-bounds read vulnerability in NVMe functionality. A malicious actor with local non-administrative access to a virtual machine with a virtual NVMe… | |
| Modificada | Crítica (9.8) | 2.9% | — | Fusionbox Widgy | 16/8/2021 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type in Django-Widgy v0.8.4 allows remote attackers to execute arbitrary code via the 'image' widget in the component 'Change Widgy Page'. | |
| Modificada | Media (4.7) | 0.45% | — | Verygoodplugins WP Fusion | 9/8/2021 | 17/6/2026 | The WP Fusion Lite WordPress plugin is vulnerable to Cross-Site Request Forgery via the `show_logs_section` function found in the ~/includes/admin/logging/class-log-handler.php file which allows attackers to drop all logs for the plugin, in versions up to and including 3.37.18. | |
| Modificada | Media (6.1) | 0.82% | — | Verygoodplugins WP Fusion | 9/8/2021 | 17/6/2026 | The WP Fusion Lite WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the startdate parameter found in the ~/includes/admin/logging/class-log-table-list.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 3.37.18. | |
| Modificada | Alta (7.5) | 2.4% | — | Oracle Advanced Networking OptionOracle Agile Engineering Data ManagementOracle Agile Product Lifecycle ManagementOracle Agile Product Lifecycle Management FOR Process+107 | 21/7/2021 | 25/8/2026 | Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Advanced Networking Option. Successful attacks… | |
| Modificada | Media (4.8) | 0.60% | — | Php-fusion | 7/7/2021 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in PHP-Fusion 9.03.60 via 'New Shout' in /infusions/shoutbox_panel/shoutbox_admin.php. | |
| Modificada | Media (5.4) | 0.45% | — | Php-fusion | 2/7/2021 | 17/6/2026 | A stored cross site scripting (XSS) vulnerability in /administration/setting_security.php of PHP-Fusion 9.03.60 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload. | |
| Modificada | Media (5.4) | 0.45% | — | Php-fusion | 2/7/2021 | 17/6/2026 | A stored cross site scripting (XSS) vulnerability in /administration/settings_registration.php of PHP-Fusion 9.03.60 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Registration" field. | |
| Modificada | Media (5.4) | 0.52% | — | Php-fusion | 2/7/2021 | 17/6/2026 | The component /php-fusion/infusions/shoutbox_panel/shoutbox_archive.php in PHP-Fusion 9.03.60 allows attackers to redirect victim users to malicious websites via a crafted payload entered into the Shoutbox message panel. | |
| Modificada | Media (5.4) | 0.45% | — | Php-fusion | 2/7/2021 | 17/6/2026 | A reflected cross site scripting (XSS) vulnerability in /administration/theme.php of PHP-Fusion 9.03.60 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Manage Theme" field. | |
| Modificada | Media (5.4) | 0.47% | — | Php-fusion | 2/7/2021 | 17/6/2026 | A stored cross site scripting (XSS) vulnerability in administration/settings_main.php of PHP-Fusion 9.03.50 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Site footer" field. | |
| Modificada | Media (5.4) | 0.52% | — | Php-fusion | 2/7/2021 | 17/6/2026 | An issue exists in PHP-Fusion 9.03.50 where session cookies are not deleted once a user logs out, allowing for an attacker to perform a session replay attack and impersonate the victim user. | |
| Modificada | Alta (7.8) | 0.50% | — | Adobe Coldfusion | 27/5/2021 | 17/6/2026 | The Adobe ColdFusion installer fails to set a secure access-control list (ACL) on the default installation directory, such as C:\ColdFusion2021\. By default, unprivileged users can create files in this directory structure, which creates a privilege-escalation vulnerability. | |
| Modificada | Media (4.3) | 0.53% | — | Huawei Fusioncompute | 27/5/2021 | 17/6/2026 | There is an insufficient input validation vulnerability in FusionCompute 8.0.0. Due to the input validation is insufficient, an attacker can exploit this vulnerability to upload any files to the device. Successful exploit may cause the service abnormal. | |
| Modificada | Media (6.5) | 2.7% | — | Nagios Fusion | 24/5/2021 | 17/6/2026 | Incorrect Access Control in Nagios Fusion 4.1.8 and earlier allows low-privileged authenticated users to extract passwords used to manage fused servers via the test_server command in ajaxhelper.php. | |
| Modificada | Alta (8.8) | 5.1% | — | Nagios Fusion | 24/5/2021 | 17/6/2026 | Incorrect File Permissions in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation to root via modification of scripts. Low-privileges users are able to modify files that can be executed by sudo. | |
| Modificada | Crítica (9.8) | 5.7% | — | Nagios Fusion | 24/5/2021 | 17/6/2026 | Command Injection in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation to nagios. | |
| Modificada | Crítica (9.8) | 3.4% | — | Nagios Fusion | 24/5/2021 | 17/6/2026 | Incorrect SSL certificate validation in Nagios Fusion 4.1.8 and earlier allows for Escalation of Privileges or Code Execution as root via vectors related to download of an untrusted update package in upgrade_to_latest.sh. |